Published By: NetworkComputing Posted By: Adam Chalemian 9/17/2002
Back in the day, patches were used to cover holes in your jeans, not in commercial software. That's not to say software didn't include "undocumented features." But the severity of defects was nowhere near the level it is today, and we could afford to postpone fixes until the rollout of a subsequent software release.
Today, patches are not only commonplace, they're expected. And not just by customers, but by vendors. When Microsoft released Windows 2000, it did so knowing that the code stream contained thousands of defects. SP1 alone fixed more than 600 of these defects (see List of Bugs Fixed in Windows 2000 Service Pack 1.") Certainly some of them were minor, but it makes you wonder how many resulted in the rampant spread of Code Red, Nimda and other viruses.
Patch management today is a full-time job. You must keep track of all the patches available and micromanage them to ensure that the changes applied through installing a patch do not adversely affect production software. Companies need a mirror of their production environment simply as a test bed for the patch o' the week. Organizations need a tracking system to ensure they know which patch was installed when and on what machines. And the poor people managing it all need a vacation.